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. Security proofs of quantum key distribution (QKD) often require post-processing schemes to 
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D ' simplify the data structure, and hence the security proof. We show a generic method to improve 

\^ ' resulting secure key rates by partially reversing the simplifying post-processing for error correction 

purposes. We apply our method to the security analysis of device-independent QKD schemes 
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and of detection-device-independent QKD schemes, where in both cases one is typically required 
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C ' to assign binary values even to lost signals. In the device-independent case, the loss tolerance 
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threshold is cut down by our method from 92.4% to 90. 9%. The lowest tolerable transmittance of 
the detector-device- independent scheme can be improved from 78.0% to 65.9%. 
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I. INTRODUCTION 



Quantum key distribution (QKD) provides a means of distributing secure keys be- 
tween two distant parties, Alice and Bob. It uses a quantum channel and an authenticated 
classical channel. The security of specific abstract QKD protocols has been proven in lit- 
erature under varying definitions of security 3|-[5|. A clear framework for security proofs 
including finite-size effects has been put forward by Renner jo]. For a review of the subject, 
refer to THSj and references therein. 

When it comes to real optical implementations, security proofs have to be able to take 
non-ideal devices into consideration. A lot of effort has been made to achieve the security of 
QKD with realistic devices 10l-ll4l|. One approach is based on exact models of the devices. As 
security proofs have to apply to the infinite- dimensional Hilbert space of optical modes, one 
seeks methods to simplify the analysis. One method is to apply coarse-graining of data, by 
which we mean a postprocessing of data. Let us give two examples for this coarse-graining. 

The first example is the random assignment of double-click events in the BB84 protocol 



with threshold detectors. This assignment allows the construction of a squashing model [14 1 
so that the security of the optical implementation can be tied directly to a corresponding 
abstract qubit protocol. 

The other example is the treatment of loss in QKD. The possibility of transmission and 
detection losses can be easily incorporated in the security proofs as long as it holds that the 
loss probability is independent of the chosen measurement basis. However, as demonstrated 



m 
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18| this assumption is violated in typical implementations by adversarial action. As 



a result, QKD schemes can be completely broken if they do not address this point. One 
way to patch this weakness is to assign measurement outcomes even to lost signals. The 
typical choice is a random assignment. In this way, signal loss is converted into an effective 
error rate on the data. Using this patch, it is now possible to circumvent the need for 
precise characterization of devices in the paradigm of device-independent (originally known 
as self-testing) QKD schemes. Since the early work by Mayers and Yao in 1998 19|], a 



few more realistic 
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2l| and generalized |22| schemes have been proposed. Recently, 



21 



2311. Besides a 



the security analysis of device- independent schemes has made progress 
missing unconditional security proof, the main drawback of these schemes are their severe 
constraints on physical devices in practice. For example, the security analysis of Pironio 
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et al. [23| gives a tolerable error rate is 7.1% which translates to a required minimum 
transmittance of 92.4%. Less restrictive schemes are detection-device-independent schemes 
which assume some generic structure on the source side, but makes no assumption on the 
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25j. The scheme by Koashi 



detection devices. Examples of this approach include 
tolerates an error rate of 11% and a lower transmittance of 65.9%. 

The postprocessings mentioned above (random assignment of data to double-clicks, ran- 
dom assignment of lost signals) are done for convenience. So for the purpose of the security 
proofs, we erase the history of the assignment, meaning that we ignore the knowledge which 
of the data have been affected by the postprocessing. It is clear that security proofs can be 
also obtained without this erasure, however, these proofs will be more complicated to ob- 
tain. In this paper we address the question whether we can improve the key rate by making 
use of our knowledge of the positions within the data string that, for example, have been 
assigned random values. We will demonstrate a generic way of making use of the knowledge, 
without the need to revisit the full security proof. Of course, this approach will work only 
if the QKD protocol and the security proof follows some generic structure. In Section HTl we 
outline these generic structures. Then, in Section IIIII we provide the generic method to use 
our extra knowledge to improve the key rate. We then illustrate the effect of our method 
for two examples, for the detector-device-independent scheme in Sec. IIII Ct and for the full 
device-independent scheme in Sec. IIII D[ 

II. PROTOCOLS AND SECURITY PROOFS 

QKD protocols typcially involve two phases: the quantum phase, in which quantum 
signals are distributed and measured, resulting in correlated classical data shared between 
Alice and Bob, and a classical phase, where these classical data are processed by classical 
communication protocols. The classial phase has the goal to establish a secure key. By 
definition, a secure key should be identical between Alice and Bob, and private (unknown 
to an eavesdropper. Eve). For an example of data processing procedures, refer to 6, Q, 
A typical classical data processing can be divided into three steps: 

1. data pre-processing, which includes 
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(a) Sifting processes: any post-selection of signals, for example based on basis 
settings or non-detection events. Sifting always uses two-way communication. 

(b) Coarse graining: data processing aiming at simplifying the data structure, such 
as random bit assignments for double clicks, or random bit assignments for non- 
detected signals; coarse graining is always a local process and does not involve 
any communication. All following steps are based on the coarse-grained data 
only, 

(c) advanced pre-processing: further pre-processing, locally or by two-way com- 
munication, based on the coarse-grained data, for example adva ntag e distillation 

especially the so-called B steps [29 



30(1), and adding noise |31| : 



(d) parameter estimation:parameter estimation of the correlations shared between 
Alice and Bob, thus drawing limits on the correlations between Alice and Eve 
by quantum mechanics. This includes the estimation of the error rate, but also 
includes the decoy state analysis [s^sJ]. 

2. error correction, which ensures the key shared by Alice and Bob to be identical; 

3. privacy amplification, which ensures the key to be private. 

In this work, we assume that the step of error correction is performed in a uni-directional 
way from one party to the other, without loss of generality from Alice to Bob. As a result, 
the final key can be determined by Alice already after the data pre-processing step, as she 
sends out error correction information to Bob which enables Bob to correct his data to 
Alice's, and the privacy amplification step can be done with a hashing function chosen by 
Alice. Our results may be extended to scenarios without this assumption, as long as Alice's 
data determine the final key. 

There are many security proofs for QKD protocols that follow the outlined procedure, see 
references in 7H9|. These proofs are using different techniques and give a rate R at which 
secure key can be generated. We illustrate our finding in the infinite key limit, denoted as 
rate Roo, although our method will be directly applicable also for any analysis that includes 
finite size statistics. For our generic protocol, this key rate takes the form 

Roo > H{A) - fH{A\B) - Jp„ (1) 
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where H{A) entropy of Alice's data after the data pre-processing step. Further, H{A\B) is 
the entropy on Ahce's data given Bob's data, so that this term amounts to the minimum 
number of bits (Shannon hmit) that Ahce has to send to Bob per retained signal in order 
for Bob to be able to correct his data to match it to Alice's data. The factor / > 1 is 
an efficiency factor that characterizes the actual error correction protocol that has been 
followed. The Shanon limit corresponds to / = 1, while in practice we find typical values 
of / G (1.1,1.25). The last term, Ipa, is some measure of Eve's information on the key, 
leading to a key reduction in privacy amplification. The form of Ipa depends on the exact 
form of the security definition of the key, the exact QKD protocol, and potentially also on 
the security proof technique. It is the latter reason that we refer to these key rates as lower 
bounds, as any valid security proof guarantees that at least this amount of secret key can be 
extracted during the QKD protocol, while improved security proofs may give higher secret 
key rates without changing the protocol. 

There are three widely used approaches for security analysis: 



1. Entanglement distillation based: Shor-Preskill [5], based on [4, l35|], with Ipa = 
h[ep], where Cp is the phase error rate of qubit signals and h[x] = — a;log2(a;) — (1 — 
x) log2(l — x) is the binary entropy function; This approach is designed for fully charac- 
terized devices and typically requires specifically constructed error correction methods 
(e.g. linear codes). 

2. Entropy based: characterized devices Based on ideas by Ben-Or, this approach 



has been advanced by Devetak and Winter 3^, and made rigerous by Renner 
In the infinite key limit, we obtain with Ipa = Xe and xe is the Holevo bound [37|] 
on Eve's information about Alice's key; this approach has been also used to prove 



device-independent QKD protocols to be secure against collective attacks |23[ |. 



3. Entropy 

Xoashi 



3ased: Complementarity This approach has been first proposed by 
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24| and recently put into a rigorous framework by Tomamichel et al. 



We obtain for qubits again Ipa = h[ep]. This approach has been suggested to 



remain valid even if uncharacterized detection devices are used. 

In all these proofs, the key rate can be viewed as the rate at which signals emerge from 
the initial data pre-processing, shortened by the amount of information of error correction 
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sent from Alice to Bob and also shortened by a privacy amplification term Ipa- As stated 
before, for our analysis the exact details of the security analysis leading to the term Ipa will 
not be important, as we will deal with the error correction part of the protocol. For this, 
however, it is important to understand how the effective key rate Roo comes about. Let us 
outline some of the approaches that deal with the influence of error correction on the key 
rate. 

The first method uses encryption of the data sent from Alice and Bob by a one-time 



pad during error correction. This idea has been proposed in [39| and later refined by |40|. 
This approach allows to decople error correction from privacy amplification. Then privacy 
amplification needs only to address the initially available correlations between Alice and Eve. 
As we use one-way error correction, Alice's data are not affected by this error correction 
at all. So we generate a secret key at rate H{A) — Ipa, but we use up secret key at a rate 
of fII{A\B) to encrypt the error correction information, resulting in the net rate shown in 
Eqn. (H]). 

The second method is to keep track of the amount of information that becomes available 
to Eve during error correction. In this approach, privacy amplification has to shorten the 
key in order to cut out not only Eve's initial correlations with Alice's data, but also those 
correlations between Alice and Eve that result from Eve listening to the extra information 
becoming available during error correction. The result is again the net rate Eqn. ([1]), though 
the argumentation behind this form differs between the different security approaches. In 
the entanglement based approach, the argumentation follows directly from the structure of 
quantum error correction codes that are used to effectively distill entanglement. In the two 
entropy based approaches, instead, one uses results that show that the entropy of Eve's 
system conditioned on Alice's data can be reduced at most by one bit per bit of data 
announced by Alice during error correction. As the amount of required key shortening 
during privacy amplification depends exactly on Eve's entropy about the key before privacy 
amplification, we obtain again the key rate shown in Eqn.([l]). 

III. ADVANCED EFFICIENT ERROR CORRECTION 

As we have seen in the previous discussion, the key rates that result form the various 
security proofs depend only on the actual amount of error correction information that is 
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being sent from Alice to Bob. Our key observation is that this amount of information can 
be reduced if Bob accesses his refined knowledge about his detection events. Moreover, 
accessing the refined information by Bob for the purpose of error correction in this setting 
does not affect the correlations between Alice and Eve, and hence does not affect the term 
Ipa- We will now make these statements more precise. For our arguments, we continue to 
refer for illustrative purposes to the asymptotic key rate in QKD, but we emphasize again 
that all arguments also hold in the case of finite key sizes. 

We start with the cost of error correction. We denote by B^^^ the refined data known to 
Bob after sifting, coarse graining and advance pre-processing. Then B^^^ are the same data, 
extended by the refined data on which the coarse-graining was based. Then it follows from 
the data-processing inequality [41|] that 

H{A\B^'^) > H{A\B^''^) 

so that we have the opportunity to enable Bob to reconcile his data with Alice's data string 
with less error correction data by making used of the refined knowledge ob Bob. 

A. Background 

Next, we need to investigate the effect the use of the refined data have on the full security 
proof, and thus on the term Ipa- If we use the method of encrypting the error correction 
information using the one-time pad encryption of the error correction information, then it is 
clear that if the larger amount H{A\B^'^^) of information is sent encypted and the resulting 
key is secure, then the security is not affected if the smaller amount of information according 
to H^AiB'^'^^) is sent, as from Eve's point of view nothing changes. However, as a result, the 
net key rate increases. Note that also the amount of encrypted error correction information 
does not change Eve's view: Eve can predict the statistics of the refined information on 
Bob's side from her eavesdropping action, and also Alice can only make use of this statistics 
to design the error correction information. 

If we use an entanglement based approach, including a structured quantum error correc- 
tion method, then the correction of bit-errors decouples from the correction of phase-errors. 
The refined data then serve as a side-information to Bob to help him to be more efficient in 
correcting the bit-errors. The correction of phase-errors (and hence the privacy amplifica- 
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tion) is not affected by this. 

Finally, using entropy-based security proof approaches, note that again the refined knowl- 
edge can be considered as local side-information at Bob's side. As it is not known to Eve 
or even Alice, it does not affect the initial correlations between Alice's and Eve's data. The 
entropy-based security proofs only count the actual number of error correction bits that 
Alice sends out to Bob to allow Bob to perform error correction. If this number goes down, 
the effective secret key rate goes up by the same amount. 

Note that all these arguments also hold in the case of finite key sizes as in all security 
proof approaches the final key size depends on the actual number of bits exchanged during 
error correction. Moreover, the decoupling arguments for error correction information and 
Ipa holds also in both cases. Therefor our method is compatible with finite size security 



proofs including 



fly, 



27 



38 



42 



43|. 



B. BB84 protocol 



To illustrate the effect of our method, let us start by considering the BB84 protocol 44 1. 
The secure key rate for the qubit based protocol is given by 



R'bbL = 1 - h[e] - h[e] (2) 

where e is the observed quantum bit error rate. This rate can be proven to be secure by 
many different methods , |2J] , where the results of Mayers and Renner can also be 



shown to hold for lossy channels. In the latter case, the base of the secret key rate are the 
detected signals. We separated the individual terms corresponding to error correction at the 
Shannon limit as H{A\B) = h[e] from the privacy amplification term Ipa = h[e]. 

In optical systems, even using ideal single photon sources as qubit sources, we need to 
deal with the fact that the detectors operate on optical modes. By assigning double clicks 
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45 1 to randomly assigned binary values, one can use the existence of a squashing model 



14l ] for the photo-detector set-up to uplift the secure key rate for the qubit protocol 
over lossy qubit channels to the the same protocol over lossy optical channels with threshold 
detectors. 

Doing the coarse-graining of assigning double-clicks to single click events, we find an 
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effective quantum bit error rate for the coarse grained data as 

e('=) = P,e, + (l-P,)i (3) 

where P, is the rate of single chcks within the detected signals, which exhibit some error 
rate Cg so that 1 — Ps is the rate double clicks, which lead through random-bit assignment 
to an error rate of 1/2. This results in a key rate 

4l4 = l-2Me(^^ (4) 

We now give Bob access to refined data, so that he knows at which positions he assigned 
random single click outcomes instead of the double click outcomes. The entropy H(A\B^^^) 
corresponds to that of an erasure channel with error rate e^, so we find 

if(A|pW) = Psh[es] + (1 - Ps) . (5) 
With that, the key rate improves over Eq. ([21) to 

4l84 = ^s(l-%.])-%(^)]. (6) 

As discussed before, the data processing inequality guarantees that this method improves 
the secret key rate. The number of double-clicks in typical experiments is not very high, so 
the difference between the two secure key rates is not very big. Our next example will show 
a scenario where the difference is more important, as there we will be forced to deal with 
loss of signal. Signal loss is by far the dominating effect in QKD secure key rates compared 
to the effect of errors within the detected signals. 



C. Detection-device-independent scheme 



In many QKD security proofs, one starts with a full characterization of sources and 
detection devices. This scenario can be relaxed by having only characterized sources, while 



the detection devices remain uncharacterized. A security proofs fol 



.owing these lines is the 
have been suggested 



one by Mayers 3|] , but also the proofs of Koashi 2J] and Tomamichel 
to have this property. However, in order to deal with transmission and detection lossses, 
one has either to assume that the detection efficiency of the receiver is basis independent, 
and then can discard all lost signals, or one does not adopt any additional assumption, and 



then has to coarse-grain the non-detection event into the (binary) outcome events in order 
for these proofs to apply directly. 

We are interested in the case where we do not make additional assumption on the receiver, 
and instead randomly assign binary values to no-click and double click events. Koashi has 
indicated that, given a source which emits signals such that the density matrix averaged over 
the signals of each basis are independent of this basis, the secret key rate for the standard 
coarse-grained data processing is given by once again by Eq. with the corresponding 
error rate given by Eq. ([3]). In that error rate, the single click probability Ps and error rate 

is now the complement not only of the double clicks, but also of the no-click events, all 
of which are now coarse-grained by mapping them into random events. 

To illustrate the improvement we perform a simulation of the observed parameters to pre- 
dict the key rates. For this purpose we will neglect detector dark counts, as our simulations 
will give secret keys only for total transmissivities of 50% and more and therefore the rate of 
detected events will, typically, be many orders of magnitude higher than the dark count rate. 
The key rates are shown in the infinite-key limit with error correction being performed in the 
ideal case reaching the Shannon limit. For sources we assume perfect single-photon sources, 
so that Pg = rj where rj is the single-photon transmissivity of the overall system, including 
transmission and detection loss. The result also hold for parametric-downconversion sources 
as long as the heralding set-up assures that for the heralded signals the average density 
matrix for the two basis is still basis independent. In this picture, the single-event error rate 
e<j is due to factors such as misalignment and decoherence mechanisms in the channel. 

The simulation result is shown in Figure [1] for the ideal case where we have no errors at 
all that orginate from single clicks (e^ = 0). Of particular interest is the threshold for the 
transmittance above which secret keys can be generated. For the standard coarse-graining 
data processing one finds for this threshold the value of 78.4% (corresponding to about 11% 
error rate), which is consistent with the result of Shor-Preskill's proof jsj. The transmittance 
threshold for the advanced data processing scheme based on the refined data is case is 65.9%. 
From the time-shift attack, we know that the lower bound of tolerable transmittance for this 
untrusted detection device case is 50% j^^l. 

To show the effect of a non-zero error rate within the single-click events, we plot the 
thresholds for the two methods as a function of the single-click event error rate eAn Figure |2j 
There is no positive key for > 11.0%, which is consistent with the result in 5|. 
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FIG. 1: Plot of key rate of the two data processing schemes for the detection-device- independent 
scheme. The lowest tolerable transmittance of the coarse-grain processing scheme is 78.4%, while 
that of refined-grain processing scheme is 65.9%. Here we assume there is no error for single-clicks 
(cs = 0) and the error correction reaches the Shannon limit. 




FIG. 2: Plot of the tolerable and r/ for the two data processing schemes. 
D. Fully device-independent scheme 

In fully device-independent QKD, none of the devices of sender and receiver are char- 
acterized. These schemes are entanglement based QKD schemes, so that Alice and Bob 

11 



have two detection devices each, while the adversary Eve is in control of the source. Alice 
and Bob each choose actively between their uncharacterized devices. Securi ty pro ofs for 



these schemes, assuming collective eavesdropping attacks, have been given in 2l|, [23|. This 



Dinary outcomes. In constrast to earlier 



23| and assign a pre-agreed fixed binary 



proof assumes that the data are coarse-grained into 
coarse-graining, we will in this case follow reference 
value to lost signals, rather than random binary values, as this gives a slight advantage. 
Note that this choice also influences the Shannon entropy H{A) in Eqn. ([1]), which is now 
less than one. The privacy amplification term is given by 

'l + ^{3/2)^-1 



(7) 



where S is the CHSH 



47l | Bell parameter. To simulate this parameter for experiments, we 
neglect the double click events, assuming a perfect photon-pair source. Within single clicks 
events on both sides, there is an observed error rate Cg when measuring in the same basis. 
We assume this error rate to be the parameter of a depolarizing channel in order to predict 
the correlations when Alice and Bob do measure in different bases in order to determine 
S. The depolarizing channel maintains the signal perfectly with probability 1 — 26^, while 
it randomizes the signal with probability 26^. A perfect signal leads to a Bell parameter 
S = 2\/2, while a randomized signals gives S = 0. The tranmittance between source and 
Alice and Bob is given by rjA and rjB respectively. 

There are three contributions to the value of S: The first describes that case when both 
sides detect single clicks, which happens with probability Pg = rjA f]B- The S parameter 
in this case is given by 2v^(l — 26^). The second contribution comes happens if both 
signals are lost, which happens with probability (1 — rjAjil — i]b)- Since the binary outcomes 
are predetermined in this case and perfectly correlated, we find S = 2. Finally, the third 
contribution has one detected photon and one lost photon. The fixed assignement leads to 
uncorrelated data between Alice and Bob, and thus to S* = 0. Overall, we find then for the 
Bell parameter 

S = 2v^(l - 2es)r]AVB + 2(1 - r]A)il - Vb) • (8) 

The key is generated by measurements where Alice and Bob perform measurements in 
identical bases. Therefore the error rate of the coarse-grained data is given by 

e('=) = P,e, + ((1 - r]B)vA + (1 - Va)vb) \ • (9) 
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Note that positions where neither Ahce nor Bob do detect a photon do no contribute to an 
error rate, as Ahce and Bob would assigned the same bit value to these events. However, 
the entropy of Alice's data is now given by H{A) = h [\tia + (1 — Va)] ■ 

Overall, this particular coarse grained data processing leads to the key rate 



R 



DI 



h 



-riA + (1 - Va) 



- h[e^'^] - h 



(10) 



For the refined data processing, Alice keeps her coarse graining method as these data 
define the key. However, Bob now accesses the refined data. The key rate is shown in Figure 
El using the same modelling as in the previous section, including the choice of = 0. In 
contrast to the detection device indepent case, we now assume the source to be symmetric 
located with respect to Alice and Bob, leading to the choice r]A = f]B = V- The tolerable 
transmittancer/ for a single link for the standard processing is 92.4% (corresponding to a total 
transmittance of f]'^, or 82.6%), which is consistent with the result shown in 2l|. With the 
advanced data processing scheme, the tolerable single link transmittance can be improved 
to 90.9%. 
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FIG. 3: Plot of key rate for the device-independent QKD scheme with a double link setup and 
VA = Vb = V- The lowest tolerable transmittance of a single link for the coarse-grain processing 
scheme is 92.4%, while that of refined-grain processing scheme is 90.9%. Here we assume there is 
no error for single-clicks (e^ = 0) and the error correction reaches the Shannon limit. 
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IV. CONCLUSION 



We presented a generic method to improve the secret key rate for quantum key distribu- 
tion systems. This method apphes in situations, where information of the receiving party 
has been coarse-grained in order to apply some security proof method. We showed that 
the refined information can be accessed for error correction purposes, thus increasing the 
effective key rate. 

While we demonstrated our method in the scenario of one-direction error correction, we 



would like to point out that the framework of Renner jo] has as its essential feature only that 
the final key is derived from the data on one side. This can also be achieved by two-way error 
correction mechanism and the key rate depends only on the actual amount of information 
leaked to the adversary during error correction. Therefore, our method can be extended 
to this situation even without encryption of the error correction information. For the same 
reason, the extension to entanglement based protocols is contained in our analysis. 
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